Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 17 November 2007 05:23:00 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/MemServ-A is a worm for the Windows platform.
W32/MemServ-A includes functionality to send notification messages to remote locations.
When first run W32/MemServ-A copies itself to <Windows>\svchost.exe.
W32/MemServ-A attempts to periodically copy itself to removable drives, including floppy drives and USB keys. The worm will attempt to create the hidden file autorun.inf on the removeable drive and copy itself to a hidden file in the same location with the filename Setup.exe. The file autorun.inf is designed to start the worm once the removable drive is connected to a uninfected computer.
The following registry entry is set in order to run W32/MemServ-A on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<Windows>\svchost.exe
W32/MemServ-A continuously listens on port 7553 for incoming TCP connections.
W32/MemServ-A logs keystrokes and launched applications on the victim computer. This information is stored in the file <System>logfile.txt.
